2
Published signals
currently linked to this company
Company intelligence
unmc.edu
This company page brings together public reporting currently associated with Unmc. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
2
currently linked to this company
0
recent published signals
1
recent published signals
0
confidence classifications
July 22, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Unmc. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, Tampa Bay Dental Implants & Prosthetics, Aligned Orthopedic Partners, South Alabama Regional Planning Commission, Pivot Health, LHC Group, Mays Housecall Home Health, and the World Trade Center Health Program. University of Nebraska Medical Center (UNMC) has discovered that a vulnerability in a third-party software application has been exploited by a threat actor, exposing patient information. UNMC learned about the vulnerability in the REDCap software application in February 2026. REDCap software is used by UNMC to support its research studies and public health activities. When UNMC learned about the vulnerability, the software was taken offline, and an investigation was launched to determine if the vulnerability had already been exploited. Assisted by third-party cybersecurity experts, UNMC determined that the vulnerability had been exploited on September 20, 2023, and access remained possible until February 3, 2026. The data review confirmed that the system contained a range of sensitive data, which varied from individual to individual depending on the nature of the research study/public health activities. That information may have included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and information created or collected in connection with a research study. Such information may have included visit dates, diagnoses, medications, laboratory results, imaging or procedure information, questionnaire responses, or other health-related information. A subset of individuals also had their Social Security numbers exposed. In total, 26,937 individuals had data exposed. Individuals whose Social Security numbers were impacted have been offered complimentary credit monitoring services. Singing River Health System, a non-profit health system with three hospitals and more than 50 clinics serving the Mississippi Gulf Coast, has started notifying patients about a hacking incident identified on or around December 21, 2025. The forensic investigation confirmed unauthorized access to its computer network between December 19, 2025, and December 21, 2025, and on February 10, 2026, it was confirmed that files containing patient information were viewed and potentially copied. Immediate Delivery of Checklist Link To Your Email Address Data exposed varied from individual to individual and may have included names in combination with one or more of the following: contact information, Social Security numbers, driver’s license numbers, dates of birth, bank account information, health insurance information, provider names, internal patient identification numbers, dates of service, medication information, and treatment and/or diagnostic information. Singing River Health System said, “We will continue to implement and evaluate enhanced safeguards and security measures to further protect our systems and continue to provide security training to our employees.” The affected individuals have been advised to monitor their accounts and explanation of benefits statements for data misuse. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected. Tampa Bay Dental Implants & Prosthetics, which also does business as Tampa Bay Dental Implants, Periodontics & Oral Surgery, a dental care provider serving the St. Petersburg and Tampa Bay area in Florida, has recently disclosed a data breach affecting 6,400 individuals. Tampa Bay Dental discovered unauthorized access to its network on January 19, 2026, when ransomware was used to encrypt files. The attack affected a legacy server that contained a backup of electronic medical records. The file review confirmed that patient data was exposed, including names, contact information, birth dates, treatment notes, and clinical histories, and for a limited number of individuals, Social Security numbers. Tampa Bay Dental has implemented additional security measures to prevent similar incidents in the future, including enhancing its security logging, strengthening server encryption, and updating access controls. Credit monitoring and identity theft protection services do not appear to have been offered to the affected individuals. The World Trade Center (WTC) Health Program, which provides no-cost healthcare services to individuals harmed by the 9/11 attack on the World Trade Center, has reported a data security incident to the HHS’ Office for Civil Rights affecting 1,071 individuals. Highly sensitive data was compromised in the incident, which occurred at a vendor, Managed Care Advisors/Sedgwick Government Solutions. Hackers accessed a server containing files associated with the WTC Health Program and exfiltrated sensitive data before encrypting files. The TridentLocker ransomware group claimed responsibility for the attack. The attack was detected by Managed Care Advisors/Sedgwick Government Solutions on December 4, 2025, and the forensic investigation confirmed that the server was first breached on November 16, 2025. Data compromised in the incident includes names, addresses, Social Security numbers, dates of birth, and protected health information. TridentLocker proceeded to leak the stolen data on its dark web data site when the ransom was not paid. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. Bethesda, Maryland-based ASC Ortho Management Company, LLC, doing business as Aligned Orthopedic Partners, has discovered unauthorized access to its email environment and the exposure of the protected health information of 7,213 individuals. The forensic investigation determined unauthorized access occurred between November 16, 2025, and December 16, 2025, during which time, emails and files may have been accessed or acquired. The file review determined on February 17, 2026, that the exposed data included names in combination with one or more of the following: date of birth, Social Security number, driver’s license or state identification number, Medicaid or Medicare number, financial account number, date(s) of service, medical provider name, mental or physical condition, medical treatment information, diagnosis or clinical information, prescription information, health insurance information, patient account number, and or medical record number. The affected individuals were notified on April 17, 2026, and complimentary identity protection services have been made available. Aligned Orthopedic Partners said steps have been taken to augment security to prevent similar incidents in the future. During that time, files containing member data were viewed or copied.
Written by UNMC strategic communications In February 2026, the University of Nebraska Medical Center (“UNMC”) learned that REDCap, a software application UNMC uses to support research studies, quality improvement projects, and public health activities, had a vulnerability that could allow an unauthorized person to gain remote access to the application. Upon learning of the vulnerability, UNMC immediately took REDCap offline and initiated an investigation with the support of third-party cybersecurity consultants. On February 18, 2026, UNMC’s investigation determined that its instance of REDCap was subject to unauthorized access between September 20, 2023 and February 3, 2026. The investigation was unable to determine whether any personal information housed in REDCap was actually accessed, though the vulnerability made such access possible. The information housed in REDCap varied by project and by individual, but could include name; identifiers such as date of birth, address, phone number, email address, and/or medical record number; and information created or collected in connection with a research study, such as clinical information, visit dates, diagnoses, medications, laboratory results, imaging or procedure information, questionnaire responses, or other health-related information. For a limited number of projects, Social Security numbers may have been collected and maintained in REDCap. In an abundance of caution, UNMC is notifying individuals whose personal information is identified in REDCap. Please note that UNMC’s review of the REDCap projects is ongoing, and UNMC will provide notice to additionally-identified individuals upon completion of the review. While UNMC does not have evidence that information was actually accessed, it is always a good idea to review statements received from healthcare providers and report any unfamiliar services or charges to the issuing entity. In addition, complimentary credit monitoring is being offered to individuals whose Social Security numbers are identified in REDCap. To help prevent an incident like this from happening again, UNMC migrated to an updated version of REDCap that was released to address the vulnerability. This new version has enhanced logging and security controls enabled. Please note, we have no indication that any other UNMC application or system was impacted; Nebraska Medicine’s clinical systems operate independently from the REDCap application and were also unaffected by this incident. For questions about this incident, UNMC encourages individuals to contact the dedicated call center at (844) 403-4589 between 8:00 a.m. and 5:30 p.m. Central Time, Monday through Friday, excluding US holidays.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Unmc.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.